Post Date: September 10, 2018
Last Updated: September 24, 2026
Introduction
SSH key-based authentication provides a secure way to connect to a Linux server without entering the account password each time.
In this setup, a Windows client uses PuTTY and PuTTYgen to generate and use an SSH key pair, while the Linux server uses OpenSSH to authenticate the connection.
SSH key authentication uses two keys:
- Private Key – Stored securely on the Windows client and should never be shared.
- Public Key – Added to the Linux user’s
authorized_keysfile.
When the client connects to the server, the SSH server verifies that the client has the corresponding private key. If authentication succeeds, the user can access the server without entering the Linux account password.
This article explains how to configure SSH key-based authentication between a Windows client and a Linux server using PuTTY and PuTTYgen.
Prerequisites
Before starting, ensure that you have:
- A Linux server with OpenSSH installed.
- SSH access to the Linux server using an existing password.
- A Windows client.
- PuTTY installed on the Windows client.
- PuTTYgen installed on the Windows client.
- A Linux user account for which SSH key authentication will be configured.
Environment Used
This example assumes:
- Linux Server: CentOS 7
- Windows Client: Windows 10
- SSH Server: OpenSSH
- SSH Client: PuTTY
- Key Generation Tool: PuTTYgen
The same general approach can also be used with other Linux distributions such as Ubuntu and Debian.
Understanding SSH Key Authentication
SSH key authentication uses a key pair consisting of a public key and a private key.
The private key remains on the client machine and must be protected carefully. The public key is placed on the Linux server in the user’s SSH configuration.
The public key is normally stored in:
~/.ssh/authorized_keys
For example, for a user named admin:
/home/admin/.ssh/authorized_keys
During authentication, the SSH server verifies that the connecting client possesses the corresponding private key.
SSH Authentication Flow
Windows Client
│
│ Private Key
▼
PuTTY
│
│ SSH Connection
▼
Linux Server
│
│ Checks Public Key
▼
~/.ssh/authorized_keys
│
▼
Authentication Successful
│
▼
SSH Session
Security Note: Never share or upload the private key to the server. Only the public key should be installed on the Linux server.
Implementation
Step 1: Install PuTTY and PuTTYgen.
Download and install PuTTY and PuTTYgen on the Windows client.
PuTTY is used to establish the SSH connection, while PuTTYgen is used to generate the SSH key pair.
Step 2: Generate an SSH Key Pair
Open PuTTYgen on the Windows machine.
Generate a new SSH key pair by following these steps:
- Open PuTTYgen.
- Select the appropriate key type supported by your environment.
- Generate the key pair.
- Move the mouse over the blank area when prompted to generate randomness.
- Enter a key passphrase.
- Save the private key securely.
- Copy the generated public key.
The passphrase provides an additional layer of protection for the private key.
Important: Keep the private key and its passphrase secure. Anyone who obtains the private key and can use it may be able to authenticate as the associated user.
Step 3: Log in to the Linux Server
Log in to the Linux server using the existing password-based SSH access.
For example:
ssh username@SERVER_IP
Replace username and SERVER_IP with the appropriate values.
Step 4: Create the .ssh Directory
Navigate to the user’s home directory:
cd ~
Check whether the .ssh directory exists:
ls -la
If it does not exist, create it:
mkdir -p ~/.ssh
Set the appropriate permissions:
chmod 700 ~/.ssh
Step 5: Add the Public Key
Navigate to the .ssh directory:
cd ~/.ssh
Create or edit the authorized keys file:
vi authorized_keys
Copy the public key generated by PuTTYgen and paste it into this file as a single line.
Alternatively, if you have copied the public key to the clipboard, you can append it using an appropriate shell command.
For example:
echo 'PASTE_PUBLIC_KEY_HERE' >> ~/.ssh/authorized_keys
Set the appropriate permissions:
chmod 600 ~/.ssh/authorized_keys
Make sure the files are owned by the correct Linux user:
chown -R username:username ~/.ssh
Replace username with the actual account name.
Important: The filename is
authorized_keys, notauthorization_keys.
Step 6: Configure PuTTY to Use the Private Key
Open PuTTY on the Windows client.
Enter the Linux server’s IP address or hostname.
Navigate to:
Connection → SSH → Auth
Under the private key configuration, select the private key file generated and saved using PuTTYgen.
If your PuTTY version provides the Credentials section, the private key option will be available there.
Step 7: Configure the SSH Username
In PuTTY, navigate to:
Connection → Data
Enter the username that corresponds to the public key installed on the server.
Alternatively, you can enter the username when PuTTY prompts for login.
For example:
login as: username
Step 8: Connect to the Linux Server
Start the SSH connection from PuTTY.
The server should recognize the public key associated with the private key configured in PuTTY.
If the private key has a passphrase, PuTTY will request it.
After successful authentication, you should receive an SSH shell without needing to enter the Linux account password.
Example:
login as: admin Authenticating with public key "admin-key" Passphrase for key "admin-key":
After entering the correct passphrase, the SSH session should open.
Step 9: Verify Key-Based Authentication
Once logged in, verify that the session was authenticated using the configured SSH key.
If troubleshooting is required, use verbose SSH output from a compatible client:
ssh -v username@SERVER_IP
For PuTTY, you can also review the session and connection logs through the PuTTY configuration options.
Troubleshooting
If SSH key authentication does not work, check the following.
Check .ssh Permissions
chmod 700 ~/.ssh chmod 600 ~/.ssh/authorized_keys
Check Ownership
chown -R username:username ~/.ssh
Verify the Public Key
Make sure the public key in:
~/.ssh/authorized_keys
matches the key pair generated by PuTTYgen.
Check the SSH Service
On CentOS 7:
systemctl status sshd
If necessary:
systemctl restart sshd
Check SSH Configuration
The SSH server configuration is normally located at:
/etc/ssh/sshd_config
Verify that public-key authentication is enabled according to the server’s SSH configuration.
After modifying the configuration, validate it before restarting SSH:
sshd -t
If the configuration is valid, restart the service:
systemctl restart sshd
Warning: Be careful when modifying SSH configuration on a remote server. Keep an existing administrative session open until the new configuration has been tested successfully so that an incorrect configuration does not lock you out.
Conclusion
SSH key-based authentication provides a convenient and secure way to access Linux servers from Windows without relying on password authentication for every login.
The process involves:
- Installing PuTTY and PuTTYgen.
- Generating a public/private SSH key pair.
- Keeping the private key securely on the Windows client.
- Adding the public key to the Linux user’s
~/.ssh/authorized_keys. - Configuring PuTTY to use the private key.
- Connecting to the Linux server using the configured key.
Using a passphrase-protected private key provides an additional layer of protection if the private key file is ever exposed.
FAQ
1. What is SSH key authentication?
SSH key authentication is a method of authenticating to an SSH server using a cryptographic key pair instead of relying solely on a password.
2. Where should the public key be stored?
The public key should be added to:
~/.ssh/authorized_keys
for the Linux user who will use the key.
3. Where should the private key be stored?
The private key should remain securely on the Windows client. It should not be copied to the Linux server or shared with other users.
Related Articles
- Bash Script to Capture Login Activity Logs
Talk to our experts
Looking for the right technology solution for your business? Our team of experts can help you with development, cloud, DevOps, design, and a wide range of other technology needs. Get in touch with our team here.